๐จ CVE-2021-37460
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
๐@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
๐จ CVE-2021-37459
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
๐@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
๐จ CVE-2021-37458
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
๐@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
๐จ CVE-2021-37457
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
๐@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
๐จ CVE-2021-37456
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the blacklist IP address (stored).
๐@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
๐จ CVE-2021-37455
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the outbound dialing plan (stored).
๐@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
๐จ CVE-2021-37454
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the line name (stored).
๐@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
๐จ CVE-2021-37453
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the extension name (stored).
๐@cveNotify
www.nch.com.au
Axon Virtual VoIP PBX & SIP Server Software for Businesses
Axon Virtual SIP-enabled PBX Software works as a full featured telephone switch for small business and call center environments for analog or VoIP.
๐จ CVE-2021-37452
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
๐@cveNotify
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
๐@cveNotify
www.nch.com.au
Telephone Conference Calling Software - Free Download
Quickly download this professional telephone conference server to quickly and easily create and use conference calling. All you need is a telephone and the internet.
๐จ CVE-2021-37451
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /msglist?mbx= (reflected).
๐@cveNotify
GitHub
poc/IVM_5.12_XSS.md at main ยท 0xfml/poc
advisories/bugs/exploits/pocs etc. Contribute to 0xfml/poc development by creating an account on GitHub.
๐จ CVE-2021-37450
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmprop?id= (reflected).
๐@cveNotify
GitHub
poc/IVM_5.12_XSS.md at main ยท 0xfml/poc
advisories/bugs/exploits/pocs etc. Contribute to 0xfml/poc development by creating an account on GitHub.
๐จ CVE-2021-37439
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
๐@cveNotify
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
๐@cveNotify
GitHub
poc/Flexiserver_6.00_LFI.md at main ยท 0xfml/poc
advisories/bugs/exploits/pocs etc. Contribute to 0xfml/poc development by creating an account on GitHub.
๐จ CVE-2021-37449
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
๐@cveNotify
GitHub
poc/IVM_5.12_XSS.md at main ยท 0xfml/poc
advisories/bugs/exploits/pocs etc. Contribute to 0xfml/poc development by creating an account on GitHub.
๐จ CVE-2021-37448
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
๐@cveNotify
Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
๐@cveNotify
GitHub
poc/IVM_5.12_XSS.md at main ยท 0xfml/poc
advisories/bugs/exploits/pocs etc. Contribute to 0xfml/poc development by creating an account on GitHub.
๐จ CVE-2021-37447
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
๐@cveNotify
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file deletion.
๐@cveNotify
www.nch.com.au
Telephone Conference Calling Software - Free Download
Quickly download this professional telephone conference server to quickly and easily create and use conference calling. All you need is a telephone and the internet.
๐จ CVE-2021-37446
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.
๐@cveNotify
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file reading.
๐@cveNotify
www.nch.com.au
Telephone Conference Calling Software - Free Download
Quickly download this professional telephone conference server to quickly and easily create and use conference calling. All you need is a telephone and the internet.
๐จ CVE-2021-37445
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
๐@cveNotify
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading.
๐@cveNotify
www.nch.com.au
Telephone Conference Calling Software - Free Download
Quickly download this professional telephone conference server to quickly and easily create and use conference calling. All you need is a telephone and the internet.
๐จ CVE-2021-37444
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.
๐@cveNotify
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function.
๐@cveNotify
www.nch.com.au
IVM Free Voicemail, Call Attendant & IVR Phone Software
IVM is a powerful IVR software for interactive voice response, voicemail & call attendant phone systems; supporting caller ID logging and multi-line support.
๐จ CVE-2021-37443
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
๐@cveNotify
NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
๐@cveNotify
www.nch.com.au
IVM Free Voicemail, Call Attendant & IVR Phone Software
IVM is a powerful IVR software for interactive voice response, voicemail & call attendant phone systems; supporting caller ID logging and multi-line support.
๐จ CVE-2021-37442
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
๐@cveNotify
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
๐@cveNotify
www.nch.com.au
IVM Free Voicemail, Call Attendant & IVR Phone Software
IVM is a powerful IVR software for interactive voice response, voicemail & call attendant phone systems; supporting caller ID logging and multi-line support.
๐จ CVE-2021-35516
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
๐@cveNotify
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
๐@cveNotify